CVE List

cve编号 漏洞描述 危险等级 包名 是否影响lns23-3 修复状态 发现时间 修复时间
CVE-2024-54661 readline.sh in socat before1.8.0.2 relies on the /tmp/$USER/stderr2 file. Moderate socat 完成修复 2025-01-10 2026-06-24
CVE-2024-53976 Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, making it u... Moderate firefox 完成修复 2025-01-10 2026-01-24
CVE-2024-53975 Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to, misle... Moderate firefox 完成修复 2025-01-10 2026-01-24
CVE-2024-53008 Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulnerability... Moderate haproxy 完成修复 2025-01-10 2026-03-19
CVE-2024-52318 Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.... Moderate tomcat 完成修复 2025-01-10 2026-06-26
CVE-2024-52317 Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by ... Moderate tomcat 完成修复 2025-01-10 2026-06-26
CVE-2024-48916 A vulnerability in the Ceph Rados Gateway (RadosGW) OIDC provider allows attackers to bypass JWT signature verification by supp... Important ceph 完成修复 2025-01-10 2025-12-29
CVE-2024-47778 GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discovered in g... Important gstreamer1-plugins-good 完成修复 2025-01-10 2026-01-05
CVE-2024-47603 GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been ... Important gstreamer1-plugins-good 完成修复 2025-01-10 2026-01-05
CVE-2024-47602 GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been ... Important gstreamer1-plugins-good 完成修复 2025-01-10 2026-01-05
CVE-2024-47599 GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been ... Important gstreamer1-plugins-good 完成修复 2025-01-10 2026-01-05
CVE-2024-47596 GStreamer is a library for constructing graphs of media-handling components. An OOB-read has been discovered in the qtdemux_par... Important gstreamer1-plugins-good 完成修复 2025-01-10 2026-01-05
CVE-2024-47546 GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in extract_... Important gstreamer1-plugins-good 完成修复 2025-01-10 2026-01-05
CVE-2024-47545 GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in qtdemux_... Important gstreamer1-plugins-good 完成修复 2025-01-10 2026-01-05
CVE-2024-47544 GStreamer is a library for constructing graphs of media-handling components. The function qtdemux_parse_sbgp in qtdemux.c is af... Important gstreamer1-plugins-good 完成修复 2025-01-10 2026-01-05
CVE-2024-47543 GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discovered in q... Important gstreamer1-plugins-good 完成修复 2025-01-10 2026-01-05
CVE-2024-47542 GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference has been discovered in ... Important gstreamer1-plugins-base 完成修复 2025-01-10 2025-12-29
CVE-2024-47541 GStreamer is a library for constructing graphs of media-handling components. An OOB-write vulnerability has been identified in ... Important gstreamer1-plugins-base 完成修复 2025-01-10 2025-12-29
CVE-2024-46955 An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading colo... Moderate ghostscript 完成修复 2025-01-10 2026-01-22
CVE-2024-46657 Artifex Software mupdf v1.24.9 was discovered to contain a segmentation fault via the component /tools/pdfextract.c. This vulne... Moderate mupdf 完成修复 2025-01-10 2026-07-13
CVE-2024-45230 An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() tem... Important python-django 完成修复 2025-01-10 2026-01-04
CVE-2024-40896 In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entit... Critical libxml2 完成修复 2025-01-10 2026-01-10
CVE-2024-38313 In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the a... Moderate firefox 完成修复 2025-01-10 2026-01-24
CVE-2024-3219 The \n “socket” module provides a pure-Python fallback to the \nsocket.socketpair() function for platforms that don’t su... Important python3.11 完成修复 2025-01-10 2026-01-08
CVE-2024-31393 Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This... Moderate firefox 完成修复 2025-01-10 2026-01-24
CVE-2024-12455 A flaw was found in Fedora 41's glibc implementation of getrandom() for ppc64le. This issue occurs due to an implementation err... Moderate glibc 完成修复 2025-01-10 2025-12-11
CVE-2024-11708 Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulner... Moderate firefox, thunderbird 完成修复 2025-01-10 2026-01-24
CVE-2024-11706 A null pointer dereference may have inadvertently occurred in pk12util, and specifically in the SEC_ASN1DecodeItem_Util fun... Moderate firefox, thunderbird 完成修复 2025-01-10 2026-01-24
CVE-2024-11703 On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication. This... Moderate firefox 完成修复 2025-01-10 2026-01-24
CVE-2024-11701 The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led t... Moderate firefox, thunderbird 完成修复 2025-01-10 2026-01-24
CVE-2024-11596 ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted ca... Important wireshark 完成修复 2025-01-10 2026-01-04
CVE-2024-11595 FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection... Important wireshark 完成修复 2025-01-10 2026-01-04
CVE-2024-11586 Ubuntu's implementation of pulseaudio can be crashed by a malicious program if a bluetooth headset is connected. Moderate pulseaudio 完成修复 2025-01-10 2026-07-10
CVE-2024-11053 When asked to both use a .netrc file for credentials and to follow HTTP \nredirects, curl could leak the password used for th... Low curl, mysql:8.0 完成修复 2025-01-10 2026-01-05
CVE-2024-10524 Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are ... Moderate wget 完成修复 2025-01-10 2026-07-13
CVE-2023-7207 Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had c... Moderate cpio 完成修复 2025-01-10 2026-01-22
CVE-2023-52890 NTFS-3G before 75dcdc2 has a use-after-free in ntfs_uppercase_mbs in libntfs-3g/unistr.c. NOTE: discussion suggests that exploi... Moderate ntfs-3g 完成修复 2025-01-10 2026-01-22
CVE-2023-52722 An issue was discovered in Artifex Ghostscript before 10.03.1. psi/zmisc1.c, when SAFER mode is used, allows eexec seeds other ... Moderate ghostscript 完成修复 2025-01-10 2026-01-22
CVE-2023-52169 The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read... Important p7zip 完成修复 2025-01-10 2025-12-30
CVE-2023-49441 dnsmasq 2.9 is vulnerable to Integer Overflow via forward_query. Important dnsmasq 完成修复 2025-01-10 2026-01-04
CVE-2023-45872 An issue was discovered in Qt before 6.2.11 and 6.3.x through 6.6.x before 6.6.1. When a QML image refers to an image whose con... Moderate qt5-qtsvg 完成修复 2025-01-10 2026-03-19
CVE-2023-32190 mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations t... Important mlocate 完成修复 2025-01-10 2025-12-29
CVE-2023-20579 Improper\nAccess Control in the AMD SPI protection feature may allow a user with Ring0\n(kernel mode) privileged access to bypa... Moderate linux-firmware 完成修复 2025-01-10 2026-03-19
CVE-2023-20577 A vulnerability was found in AMD hardware due to a heap overflow in the SMM module. This issue could allow a local unauthentica... Important linux-firmware 完成修复 2025-01-10 2026-01-05
CVE-2023-20576 A vulnerability was found in AMD hardware due to insufficient verification of data authenticity in AGESA. This issue may allow ... Important linux-firmware 完成修复 2025-01-10 2026-01-05
CVE-2022-48623 The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sens... Critical perl-Cpanel-JSON-XS 完成修复 2025-01-10 2026-01-10
CVE-2022-31783 Liblouis 3.21.0 has an out-of-bounds write in compileRule in compileTranslationTable.c, as demonstrated by lou_trace. Moderate liblouis 完成修复 2025-01-10 2026-03-27
CVE-2022-30333 RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operatio... Moderate unrar 完成修复 2025-01-10 2026-06-26
CVE-2022-20001 fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git repositor... Important fish 完成修复 2025-01-10 2026-01-07
CVE-2021-41731 Cross Site Scripting (XSS vulnerability exists in )Sourcecodester News247 News Magazine (CMS) PHP 5.6 or higher and MySQL 5.7 o... Moderate mysql, php 完成修复 2025-01-10 2026-03-19
CVE-2021-3939 Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_loc... Important accountsservice 完成修复 2025-01-10 2026-01-06
CVE-2021-37311 Buffer Overflow vulnerability in fcitx5 5.0.8 allows attackers to cause a denial of service via crafted message to the applicat... Important fcitx 完成修复 2025-01-10 2026-01-07
CVE-2021-3596 A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This... Moderate ImageMagick 完成修复 2025-01-10 2026-03-19
CVE-2021-29063 A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Mpmath v1.0.0 through v1.2.1 when the mpmathify ... Important python-mpmath 完成修复 2025-01-10 2026-01-04
CVE-2021-24000 A race condition with requestPointerLock() and setTimeout() could have resulted in a user interacting with one tab when they be... Low firefox 完成修复 2025-01-10 2026-01-24
CVE-2020-36774 plugins/gtk+/glade-gtk-box.c in GNOME Glade before 3.38.1 and 3.39.x before 3.40.0 mishandles widget rebuilding for GladeGtkBox... Moderate glade, glade3 完成修复 2025-01-10 2026-03-19
CVE-2019-11250 The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unau... Moderate kubernetes 完成修复 2025-01-10 2026-03-19
CVE-2015-8126 Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x befor... Important libpng 完成修复 2025-01-10 2026-01-05
CVE-2015-5722 buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of serv... Important bind 完成修复 2025-01-10 2026-01-06
CVE-2015-5289 Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow att... Moderate postgresql 完成修复 2025-01-10 2026-01-22
CVE-2015-5288 The crypt function in contrib/pgcrypto in PostgreSQL before 9.0.23, 9.1.x before 9.1.19, 9.2.x before 9.2.14, 9.3.x before 9.3.... Moderate postgresql 完成修复 2025-01-10 2026-01-22
CVE-2015-4620 name.c in named in ISC BIND 9.7.x through 9.9.x before 9.9.7-P1 and 9.10.x before 9.10.2-P2, when configured as a recursive res... Important bind 完成修复 2025-01-10 2026-01-06
CVE-2015-4498 The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to ... Important firefox 完成修复 2025-01-10 2025-12-29
CVE-2015-3415 The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows co... Important sqlite 完成修复 2025-01-10 2026-01-09
CVE-2015-3414 SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attac... Important sqlite 完成修复 2025-01-10 2026-01-09
CVE-2015-3213 The gesture handling code in Clutter before 1.16.2 allows physically proximate attackers to bypass the lock screen via certain ... Important clutter 完成修复 2025-01-10 2026-01-08
CVE-2015-1863 Heap-based buffer overflow in wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (crash), read... Moderate wpa_supplicant 完成修复 2025-01-10 2026-03-19
CVE-2015-1792 The do_free_upto function in crypto/cms/cms_smime.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.... Moderate openssl 完成修复 2025-01-10 2026-01-25
CVE-2015-1791 Race condition in the ssl3_get_new_session_ticket function in ssl/s3_clnt.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0... Moderate openssl 完成修复 2025-01-10 2026-01-25
CVE-2015-1790 The PKCS7_dataDecodefunction in crypto/pkcs7/pk7_doit.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, an... Moderate openssl 完成修复 2025-01-10 2026-01-22
CVE-2015-0836 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Th... Moderate firefox 完成修复 2025-01-10 2026-01-24
CVE-2015-0293 The SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a allows re... Moderate openssl 完成修复 2025-01-10 2026-01-22
CVE-2015-0292 Integer underflow in the EVP_DecodeUpdate function in crypto/evp/encode.c in the base64-decoding implementation in OpenSSL befo... Important openssl 完成修复 2025-01-10 2026-01-09
CVE-2015-0289 The PKCS#7 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not... Moderate openssl 完成修复 2025-01-10 2026-01-22
CVE-2015-0287 The ASN1_item_ex_d2i function in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, an... Moderate openssl 完成修复 2025-01-10 2026-01-22
CVE-2015-0286 The ASN1_TYPE_cmp function in crypto/asn1/a_type.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0... Moderate openssl 完成修复 2025-01-10 2026-01-22
CVE-2015-0209 Use-after-free vulnerability in the d2i_ECPrivateKey function in crypto/ec/ec_asn1.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.... Moderate openssl 完成修复 2025-01-10 2026-01-22
CVE-2014-8176 The dtls1_clear_queues function in ssl/d1_lib.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h frees d... Important openssl 完成修复 2025-01-10 2026-01-09
CVE-2013-6393 The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote atta... Moderate libyaml 完成修复 2025-01-10 2026-01-22
CVE-2025-0243 Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird 128.5. Some of these bugs showed... Moderate firefox, thunderbird 完成修复 2025-01-09 2026-01-24
CVE-2025-0242 Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, and Thun... Important firefox, thunderbird 完成修复 2025-01-09 2025-12-29
CVE-2025-0241 When segmenting specially crafted text, segmentation would corrupt memory leading to a potentially exploitable crash. This vuln... Moderate firefox, thunderbird 完成修复 2025-01-09 2026-01-24
CVE-2025-0240 Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-... Moderate firefox, thunderbird 完成修复 2025-01-09 2026-01-24
CVE-2025-0239 When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. Th... Moderate firefox, thunderbird 完成修复 2025-01-09 2026-01-24
CVE-2025-0238 Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploi... Moderate firefox, thunderbird 完成修复 2025-01-09 2026-01-24
CVE-2025-0237 The WebChannel API, which is used to transport various information across processes, did not check the sending principal but ra... Moderate firefox, thunderbird 完成修复 2025-01-09 2026-01-24
CVE-2024-53580 iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function. Important iperf3 完成修复 2025-01-09 2026-01-06
CVE-2024-8508 NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRsets tha... Moderate unbound 完成修复 2025-01-07 2026-06-24
CVE-2024-50106 In the Linux kernel, the following vulnerability has been resolved:nfsd: fix race between laundromat and free_stateidThere is a... Moderate kernel:5.10, kernel:4.19 完成修复 2024-12-30 2026-01-19
CVE-2024-40725 A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based... Important httpd 完成修复 2024-12-27 2026-01-09
CVE-2024-39884 A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handle... Important httpd 完成修复 2024-12-27 2026-01-09
CVE-2024-56337 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.... Moderate tomcat 完成修复 2024-12-21 2026-06-26
CVE-2024-49985 In the Linux kernel, the following vulnerability has been resolved: Moderate kernel:5.10, kernel:4.19, kernel:6.6 完成修复 2024-12-20 2026-01-19
CVE-2024-49952 In the Linux kernel, the following vulnerability has been resolved: Moderate kernel:5.10, kernel:4.19, kernel:6.6 完成修复 2024-12-20 2026-01-19
CVE-2024-49889 In the Linux kernel, the following vulnerability has been resolved: Moderate kernel:5.10, kernel:4.19 完成修复 2024-12-20 2026-01-19
CVE-2024-49882 In the Linux kernel, the following vulnerability has been resolved: Moderate kernel:5.10, kernel:4.19 完成修复 2024-12-20 2026-01-19
CVE-2024-49878 In the Linux kernel, the following vulnerability has been resolved: Moderate kernel:5.10, kernel:4.19, kernel:6.6 完成修复 2024-12-20 2026-01-19
CVE-2024-49862 RESERVED This candidate has been reserved by an organization or individual that will use it when announcing a new securit... Moderate kernel:5.10, kernel:4.19, kernel:6.6 完成修复 2024-12-20 2026-01-19
CVE-2024-47731 In the Linux kernel, the following vulnerability has been resolved: Moderate kernel:5.10, kernel:4.19, kernel:6.6 完成修复 2024-12-20 2026-01-19
CVE-2024-47730 In the Linux kernel, the following vulnerability has been resolved: Moderate kernel:5.10, kernel:4.19, kernel:6.6 完成修复 2024-12-20 2026-01-19

第1页 | 上一页| 下一页 | 最后一页

©龙芯开源社区 all right reserved,powered by Gitbook文档更新时间: 2026-08-05 21:34:31

results matching ""

    No results matching ""

    results matching ""

      No results matching ""